Impact
The vulnerability is improper access control (CWE‑284) in the Windows DNS client that permits an authorized user to tamper with DNS client settings locally. The description indicates that such tampering could alter the client configuration or behavior on the infected machine, potentially compromising the integrity of DNS resolution on that host.
Affected Systems
Affected systems include Microsoft Windows 11 version 24H2, 25H2, and 26H1, as well as Microsoft Windows Server 2025 (including Server Core installations).
Risk and Exploitability
The CVSS score of 7.1 places the vulnerability in the moderate severity range. The EPSS score of less than 1 % indicates a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local: an attacker must have authorized user privileges on a target device to modify DNS configuration, which could affect the confidentiality, integrity, and availability of DNS resolution for that host.
OpenCVE Enrichment